SneakLeak: Detecting multipartite leakage paths in Android apps

被引:6
|
作者
Bhandari, Shweta [1 ]
Herbreteau, Frederic [2 ]
Laxmi, Vijay [1 ]
Zemmari, Akka [2 ]
Roop, Partha S. [3 ]
Gaur, Manoj Singh [1 ]
机构
[1] Malaviya Natl Inst Technol Jaipur, Dept Comp Sci & Engn, Jaipur, Rajasthan, India
[2] Univ Bordeaux, CNRS, LaBRI, F-33405 Talence, France
[3] Univ Auckland, Dept Elect & Comp Engn, Auckland, New Zealand
关键词
App Collusion; Multi-app Analysis; Verification; Model checking; Information Leakage; Permission Escalation;
D O I
10.1109/Trustcom/BigDataSE/ICESS.2017.249
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, a technique is proposed to address the threat emerging from multiple colluding Android applications (apps). Existing techniques have focused on single app analysis which may be defeated by scattering leakage-capable path segments across multiple apps. In such a scenario, individual app shall appear benign. Whereas, together with other conspiring apps, if present, can lead to information leakage. This threat is known as app collusion. Relay of private and sensitive information from one app to another is possible via multiple communication mechanisms provided by Android. In this paper, we present SneakLeak, a new model-checking based technique for detection of app collusion. The proposed method analyze multiple apps simultaneously. SneakLeak can identify any set of conspiring apps that might be involved in the collusion. To demonstrate the efficacy of our proposal, we experimented with Android apps exhibiting collusion through inter-app communication. The apps are taken from test dataset named DroidBench. Our experiments show that the technique can precisely detect the presence/absence of collusion among apps.
引用
收藏
页码:285 / 292
页数:8
相关论文
共 50 条
  • [1] Detecting Data Leakage from Databases on Android Apps with Concept Drift
    Kul, Gokhan
    Upadhyaya, Shambhu
    Chandola, Varun
    2018 17TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (IEEE TRUSTCOM) / 12TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING (IEEE BIGDATASE), 2018, : 905 - 913
  • [2] Detecting Antipatterns in Android Apps
    Hecht, Geoffrey
    Rouvoy, Romain
    Moha, Naouel
    Duchien, Laurence
    2ND ACM INTERNATIONAL CONFERENCE ON MOBILE SOFTWARE ENGINEERING AND SYSTEMS MOBILESOFT 2015, 2015, : 148 - 149
  • [3] Detecting Connectivity Issues in Android Apps
    Mazuera-Rozo, Alejandro
    Escobar-Velasquez, Camilo
    Espitia-Acero, Juan
    Linares-Vasquez, Mario
    Bavota, Gabriele
    2022 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE ANALYSIS, EVOLUTION AND REENGINEERING (SANER 2022), 2022, : 697 - 708
  • [4] On Automatically Detecting Similar Android Apps
    Linares-Vasquez, Mario
    Holtzhauer, Andrew
    Poshyvanyk, Denys
    2016 IEEE 24TH INTERNATIONAL CONFERENCE ON PROGRAM COMPREHENSION (ICPC), 2016,
  • [5] Improving Leakage Path Coverage in Android Apps
    Modi, Garima
    Laxmi, Vijay
    Naval, Smita
    Gaur, Manoj Singh
    2017 16TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS / 11TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING / 14TH IEEE INTERNATIONAL CONFERENCE ON EMBEDDED SOFTWARE AND SYSTEMS, 2017, : 355 - 362
  • [6] Detecting Display Energy Hotspots in Android Apps
    Wan, Mian
    Jin, Yuchen
    Li, Ding
    Halfond, William G. J.
    2015 IEEE 8TH INTERNATIONAL CONFERENCE ON SOFTWARE TESTING, VERIFICATION AND VALIDATION (ICST), 2015,
  • [7] Detecting and Measuring Misconfigured Manifests in Android Apps
    Yang, Yuqing
    Elsabagh, Mohamed
    Zuo, Chaoshun
    Johnson, Ryan
    Stavrou, Angelos
    Lin, Zhiqiang
    Proceedings of the ACM Conference on Computer and Communications Security, 2022, : 3063 - 3077
  • [8] Detecting display energy hotspots in Android apps
    Wan, Mian
    Jin, Yuchen
    Li, Ding
    Gui, Jiaping
    Mahajan, Sonal
    Halfond, William G. J.
    SOFTWARE TESTING VERIFICATION & RELIABILITY, 2017, 27 (06):
  • [9] Defining and Detecting Environment Discrimination in Android Apps
    Hong, Yunfeng
    Hu, Yongjian
    Lai, Chun-Ming
    Wu, S. Felix
    Neamtiu, Iulian
    McDaniel, Patrick
    Yu, Paul
    Cam, Hasan
    Ahn, Gail-Joon
    SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM 2017, 2018, 238 : 510 - 529
  • [10] PDroid: Detecting Privacy Leakage on Android
    Zhang, Pu-han
    Li, Jing-zhe
    Shao, Shuai
    Wang, Peng
    MECHATRONICS ENGINEERING, COMPUTING AND INFORMATION TECHNOLOGY, 2014, 556-562 : 2658 - 2662